CVE-2004-2491
Opera Web Browser 7.53 - Location Replace URI Obfuscation
Severity Score
2.6
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
4
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been loaded, which allows remote attackers to spoof the URL in the address bar via the window.open and location.replace HTML parameters, which facilitates phishing attacks.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2004-07-27 First Exploit
- 2004-12-31 CVE Published
- 2005-10-25 CVE Reserved
- 2023-03-07 EPSS Updated
- 2024-08-08 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
https://exchange.xforce.ibmcloud.com/vulnerabilities/16816 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/24325 | 2004-07-27 | |
http://archives.neohapsis.com/archives/fulldisclosure/2004-07/1056.html | 2024-08-08 | |
http://www.osvdb.org/8317 | 2024-08-08 | |
http://www.securityfocus.com/bid/10810 | 2024-08-08 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/12162 | 2022-02-28 | |
http://www.opera.com/windows/changelogs/754 | 2022-02-28 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Opera Search vendor "Opera" | Opera Browser Search vendor "Opera" for product "Opera Browser" | <= 7.53 Search vendor "Opera" for product "Opera Browser" and version " <= 7.53" | - |
Affected
|